How to find shadow AI in your organisation
The AI your organisation uses without knowing it leaves traces in systems you already run. Where to look, how to correlate what you find and how to bring it into governance without turning discovery into a witch hunt.
How do you find the AI your organisation is using without approval?
Shadow AI leaves traces in systems you already run, so finding it is a correlation exercise rather than a survey. The productive sources are your identity provider, which records sign-ons to AI services with work accounts, your finance system, which records the subscriptions teams put on corporate cards, your device management, which records the AI applications installed on managed machines, your cloud inventories, which record AI services stood up in your own tenancy, your network egress, which records traffic to AI endpoints, and your ITSM and workspace tools. No single source gives the whole picture. Cross-referencing them turns scattered hits into a defensible list of what is actually in use, which then needs a human decision to bring each finding into the register or retire it.
Every organisation using software is using more AI than it knows. Teams subscribe to tools on corporate cards, staff sign into assistants with their work accounts and vendors switch on AI features inside products you bought for something else. None of it announces itself to whoever keeps the AI register, and all of it carries the risks the register exists to govern. The good news is that shadow AI leaves traces, and the traces live in systems you already run.
Why surveys don’t work
The instinctive first move is to ask. A survey goes out, teams respond with what they remember and consider worth mentioning, and the result understates reality for reasons that have nothing to do with bad faith. People forget the tool they trialled in March, do not think of the AI feature inside their CRM as “using AI” and hesitate to volunteer the subscription nobody approved. Surveys are worth running once for the signal they give about awareness, but a register built on self-reporting alone is a register of what people admit to.
Where the traces are
The productive sources, roughly in order of how much they usually yield, are these.
Your identity provider sees sign-ons. When staff use their work accounts with AI services, the sign-on events are already in your identity platform, and they are the single richest source because they capture usage rather than intent.
Your finance system sees subscriptions. AI tools cost money, and the charges land in your accounting platform with merchant names that identify them. Finance data catches the paid tools that identity data alone can miss, and it names the team that pays.
Your device management sees installations. Managed devices report their installed applications, which catches desktop AI tools and the browsers’ AI extensions, especially when browser management is in place.
Your cloud inventories see what your own builders stand up. AI services in your own cloud tenancy, from model endpoints to AI-enabled data services, appear in the cloud provider’s own inventory, and internal builds are the shadow AI with the deepest data access.
Your network egress sees traffic. Requests to AI endpoints from inside your network are visible in egress logs, which catches usage that touches nothing else you manage.
Your ITSM and workspace tools see the rest, meaning the software recorded in your CMDB whose AI features nobody flagged, and the AI apps installed into your messaging and collaboration platforms.
Correlation is the actual work
Any one source produces hits. The work is resolving them, because the same tool appears as a sign-on event, a card charge and an installed application, and treated separately those are three mysteries instead of one finding. Cross-referencing collapses the noise, because the sign-on names the users, the charge names the paying team and the device data names the machines, and together they describe one system with enough context to make a decision about. Do this in a spreadsheet if your footprint is small. It stops being manageable by hand quickly.
From finding to governance
A discovery finding is not a register entry, it is a question. Someone has to decide whether the thing found becomes a governed system with a named owner, gets retired with its users pointed at a sanctioned alternative, or needs investigating first. The decision should be recorded whichever way it goes, because a documented “we found it, assessed it and retired it” is governance working, and an unexplained distance between what discovery found and what the register holds is the opposite.
Run it as hygiene, not as a hunt. The point of discovery is a true register, not catching people, and the organisations that treat found users as offenders teach everyone to hide better. Most shadow AI is people trying to do their jobs with the best tool they could find, which is information about unmet demand as much as it is a governance finding.
Where Aicura fits
Aicura’s discovery does the reading and the correlating. Connectors cover identity providers, device management, cloud inventories, IT service management, code hosting, finance systems, browsers and workspace tools, and correlated findings arrive as suggestions with their evidence attached. A person accepts each suggestion into the AI Register, dismisses it or holds it, and the decision is recorded, so the register stays something your organisation decided rather than something a scanner emitted. Discovery scans, the queue and the decisions are included from the free Register tier, with the finance and network egress connectors joining at Pro.
Aicura provides guidance, not legal advice, and does not certify, audit or issue a compliance verdict. What your organisation does about each finding stays its call.
Common questions
Is shadow AI actually a problem if the tools are good? The tools being good is not the issue. The issue is that ungoverned AI carries the same risks as governed AI, meaning data leaving your control, decisions affecting people and obligations you may already hold, with nobody accountable and no record. Some shadow AI, once found, is worth adopting properly. The problem is not knowing.
Should we block AI services instead of discovering them? Blanket blocking mostly relocates the behaviour to personal devices and personal accounts, where you have no visibility at all. Discovery plus a sanctioned path works better, because most people using shadow AI are trying to do their jobs, not to defy you. Enforcement has its place for specific rules, applied through guardrails rather than a wall.
How often should discovery run? Continuously or on a regular schedule, not as a one-off project. The AI footprint changes every month as teams adopt tools and vendors switch on AI features inside software you already run. A discovery exercise dated last year describes last year.
What do we do with what we find? Decide, one finding at a time. Each finding is accepted into the AI Register with a named owner, retired with the users pointed at a sanctioned alternative, or held for investigation. Recording the decision matters as much as making it, because the decision trail is what shows your organisation responded to what it learned.
A note on this page
This guide describes an approach to finding ungoverned AI, not a compliance procedure, and reading source systems like identity logs and device inventories should be done within your organisation’s own privacy, employment and monitoring policies. Take your own advice on those before you start.
Related guides
- How to build an AI system register — Where the findings go once you have them.
- Which systems make automated decisions
- How to run an AI risk assessment
Run the search with Aicura
Aicura's discovery connects to your identity, device, cloud, ITSM, code and workspace sources, correlates the signals into suggestions and records the decision on each. It is included from the free Register tier, so finding out costs nothing.